网络安全风险评估
Cybersecurity risk assessment 说明 CRA 产品安全要求如何适用于一个 product with digital elements。它把产品的 intended purpose、foreseeable use、conditions of use、资产、风险、安全措施和 technical documentation 连接起来。
风险评估的作用
For the purpose of complying with paragraph 1, manufacturers shall undertake an assessment of the cybersecurity risks associated with a product with digital elements and take the outcome of that assessment into account during the planning, design, development, production, delivery and maintenance phases of the product with digital elements with a view to minimising cybersecurity risks, preventing incidents and minimising their impact, including in relation to the health and safety of users.
Regulation (EU) 2024/2847, Article 13(2)
这不是一次性表格。Article 13 将风险评估放进产品生命周期,并要求在 support period 内按需要更新。
风险评估需要说明什么
Article 13(3) 给出最低逻辑。评估必须考虑 intended purpose、reasonably foreseeable use、conditions of use、运行环境、需要保护的资产,以及预期使用时间。
- 哪些 Annex I Part I 要求适用于该产品;
- 这些产品要求如何被实现;
- Annex I Part I point (1) 的一般风险化网络安全要求如何适用;
- Annex I Part II 的 vulnerability-handling 要求如何适用;
- 如果 manufacturer 认为某项要求不适用,理由是什么。
技术文件连接
Article 13(4) 要求把 cybersecurity risk assessment 纳入 technical documentation。Annex VII 进一步要求文件包括评估产品在设计、开发、生产、交付和维护时所针对的网络安全风险。
分析范围
产品事实、使用方式、环境、资产、威胁、漏洞和误用场景。
安全措施
产品属性、安全控制、更新设计和 vulnerability-handling 措施。
生命周期更新
产品变更、新漏洞、新证据和 support period 变化可能触发重新评估。
证据文件
结论属于 technical documentation,并支撑 conformity assessment。
标准支持
草案 prEN 40000-1-2 页面说明当前横向 cyber-resilience 风险管理原则文件。它可以帮助组织工作,但法律义务仍来自 Article 13 和 Annex I。